1Parties
This Data Processing Agreement (this "DPA") is entered into between:
(a) Klarivox ApS, CVR no. 46445104, a Danish private limited company (anpartsselskab) with its registered office at Glamsbjergvej 15, 2770 Kastrup, Denmark (the "Processor" or "Klarivox"); and
(b) the entity identified as "Customer" in Annex I to this DPA (the "Controller").
Each a "Party" and together the "Parties."
2Background and Structure
2.1 The Controller and Klarivox have entered into a separate agreement under which Klarivox provides the Klarivox software-as-a-service platform to the Controller (the "Principal Agreement"). In delivering the Klarivox platform, Klarivox processes personal data on behalf of the Controller.
2.2 This DPA sets out the terms on which Klarivox processes such personal data, and forms part of the Principal Agreement. In the event of a conflict between this DPA and the Principal Agreement, this DPA prevails on matters of data protection. In the event of a conflict between the body of this DPA and the Standard Contractual Clauses incorporated under clause 11, the Standard Contractual Clauses prevail.
2.3 The Annexes form an integral part of this DPA: Annex I (Description of processing), Annex II (Technical and organisational measures), Annex III (Sub-processors).
3Definitions
4Roles of the Parties
4.1 The Parties acknowledge and agree that, in respect of the processing of Customer Personal Data under the Principal Agreement, the Controller is the controller and Klarivox is the processor.
4.2 The Controller is responsible for ensuring that it has a valid lawful basis under Applicable Data Protection Law for the processing carried out by Klarivox on its behalf, that all necessary notices have been provided to data subjects, and that any required consents have been obtained.
4.3 The Controller warrants that its instructions to Klarivox comply with Applicable Data Protection Law and that it has the right to disclose the Customer Personal Data to Klarivox for the purposes of the Principal Agreement.
5Scope of Processing
The subject matter, duration, nature and purpose of the processing, the types of personal data processed, and the categories of data subjects are set out in Annex I.
6Processing on Documented Instructions
6.1 Klarivox shall process Customer Personal Data only on the documented instructions of the Controller, including with regard to transfers of Customer Personal Data to a third country, unless required to do otherwise by EU or Member State law. In such a case, Klarivox shall inform the Controller before processing, unless that law prohibits such information on grounds of public interest.
6.2 The Controller's documented instructions are constituted by: (a) the Principal Agreement; (b) this DPA and its Annexes; (c) the configuration settings, integrations, and inputs the Controller chooses within the Klarivox platform; and (d) any further written instructions agreed between the Parties.
6.3 If Klarivox is of the opinion that an instruction of the Controller infringes Applicable Data Protection Law, Klarivox shall notify the Controller without undue delay and may suspend performance of the affected instruction until the Controller confirms or modifies it.
7Confidentiality of Personnel
Klarivox shall ensure that any person authorised to process Customer Personal Data on its behalf has committed to confidentiality — either contractually or by statutory obligation — and is reliably trained in the protection of personal data.
8Security of Processing
8.1 Klarivox shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR. The specific measures Klarivox commits to are set out in Annex II.
8.2 In assessing the appropriate level of security, the Parties shall take account of the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the risk to the rights and freedoms of natural persons.
8.3 Klarivox may update the measures in Annex II provided that any updated measures do not materially diminish the overall level of protection of Customer Personal Data.
9Sub-processors
9.1 The Controller grants Klarivox a general authorisation to engage Sub-processors. The current list is set out in Annex III and is maintained under the heading "Sub-processors of customer data" at getklarivox.com/subprocessors. Other service providers listed separately on that page do not process Customer Personal Data and are not Sub-processors for the purposes of this DPA.
9.2 Klarivox shall: (a) enter into a written agreement with each Sub-processor imposing data-protection obligations no less protective than those in this DPA, to the extent applicable to the nature of services provided; (b) remain fully liable to the Controller for any failure by a Sub-processor to fulfil its data-protection obligations.
9.3 Klarivox shall give the Controller at least thirty (30) days' prior written notice of any intended addition or replacement of a Sub-processor engaged directly by Klarivox. Where an existing Sub-processor intends to add or replace a further Sub-processor, Klarivox shall notify the Controller without undue delay after receiving notice and, where reasonably possible, before that change takes effect. The Controller may object on reasonable, documented data-protection grounds before the applicable change takes effect. If no solution can be agreed within thirty (30) days of the Controller's objection, the Controller may terminate the affected portion of the Principal Agreement on written notice, without further liability in respect of that portion (save for fees accrued before termination).
9.4 Notices of new or replacement Sub-processors are given by email to the workspace administrator and by publication at getklarivox.com/subprocessors. The Controller may subscribe to email notifications by writing to privacy@getklarivox.com.
10Assistance with Data Subject Rights
10.1 Taking into account the nature of the processing, Klarivox shall assist the Controller in fulfilling its obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR.
10.2 If Klarivox receives a data subject request directly relating to Customer Personal Data, Klarivox shall not respond other than to direct the data subject to contact the Controller, and shall forward the request to the Controller without undue delay.
10.3 Klarivox shall, on the Controller's request, provide reasonable assistance to access, rectify, delete, restrict, and export Customer Personal Data, and shall respond to any such request without undue delay.
11International Transfers
11.1 Klarivox may transfer Customer Personal Data outside the EEA to its Sub-processors or authorised personnel only where a valid transfer mechanism under Chapter V of the GDPR applies, including an adequacy decision under Article 45 or appropriate safeguards under Article 46.
11.2 To the extent any transfer of Customer Personal Data from the Controller (data exporter) to Klarivox (data importer) constitutes a Restricted Transfer, the Parties incorporate by reference the SCCs (Commission Implementing Decision 2021/914) on the following basis:
- Module Two (Controller-to-Processor) applies.
- Clause 7 (Docking clause) applies.
- Clause 9(a) Option 2 (general written authorisation) applies, with the notice periods set out in clause 9.3.
- Clause 11(a) (Independent dispute resolution body) does not apply.
- Clause 17 (Governing law): the laws of Denmark.
- Clause 18 (Forum): the courts of Denmark.
- Annexes I.A, I.B, I.C and II of the SCCs are populated by Annexes I and II of this DPA. Annex III of the SCCs is populated by Annex III of this DPA.
11.3 Klarivox stores Customer Personal Data in the EEA. Where a Sub-processor listed in Annex III, or its authorised personnel, accesses Customer Personal Data from outside the EEA for administration, security, or support, that access is permitted only under a valid Chapter V transfer mechanism. The mechanism applicable to each Sub-processor is stated in Annex III and at getklarivox.com/subprocessors.
11.4 Klarivox shall, on the Controller's reasonable request, provide information necessary to demonstrate that an appropriate transfer mechanism is in place, including a summary of any Transfer Impact Assessment Klarivox has carried out.
12Personal Data Breach
12.1 Klarivox shall notify the Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
12.2 The notification shall, to the extent then known, include: (a) the nature of the breach; (b) categories and approximate number of data subjects and records affected; (c) likely consequences; (d) measures taken or proposed to address and mitigate the breach; and (e) a contact for further information.
12.3 Where all information is not available at the same time, Klarivox shall provide it in phases without further undue delay.
12.4 Klarivox shall promptly investigate, contain, and remediate the breach, and shall provide such cooperation and information as the Controller reasonably requires to fulfil its notification obligations under Articles 33 and 34 of the GDPR.
12.5 Klarivox's notification of a Personal Data Breach shall not be construed as an acknowledgement of fault or liability.
13Data Protection Impact Assessments
Taking into account the nature of the processing and information available to it, Klarivox shall provide reasonable assistance to the Controller in connection with the Controller's obligations under Articles 32 to 36 of the GDPR, including data protection impact assessments and prior consultations with supervisory authorities. Klarivox may charge a reasonable fee for assistance that goes materially beyond standard customer support, provided that fee is notified to the Controller in advance.
14Audits and Inspections
14.1 Klarivox shall make available to the Controller all information reasonably necessary to demonstrate compliance with Article 28 of the GDPR and this DPA. On written request, Klarivox shall provide a copy of its current security documentation, including the technical and organisational measures set out in Annex II, a security overview, responses to the Controller's security questionnaire, and, once available, the executive summary of its most recent independent penetration test, in each case under appropriate confidentiality obligations.
14.2 Where clause 14.1 is insufficient to demonstrate compliance, the Controller (or an independent third-party auditor reasonably acceptable to Klarivox) may, on at least thirty (30) days' prior written notice and not more than once in any twelve (12) month period (except following a Personal Data Breach or supervisory authority order), conduct an audit of Klarivox's processing of Customer Personal Data.
14.3 Audits shall be: (a) conducted during normal business hours; (b) structured so as not to unreasonably interfere with operations; (c) subject to the auditor entering into confidentiality undertakings; (d) conducted without access to other customers' data, Klarivox's commercially sensitive information, or access that would compromise system security. Each Party bears its own audit costs, except Klarivox shall reimburse the Controller's reasonable costs where the audit identifies a material breach of this DPA by Klarivox.
15Return or Deletion of Customer Personal Data
15.1 On termination or expiry of the Principal Agreement, Klarivox shall, at the choice of the Controller, return or delete all Customer Personal Data, and delete existing copies, save where storage is required by EU or Member State law.
15.2 Unless the Controller instructs otherwise within thirty (30) days of termination, Klarivox shall delete all Customer Personal Data within ninety (90) days after termination. Copies in routine encrypted backups shall be deleted as those backups rotate, within ninety (90) days of that deletion, and shall be isolated from further processing until then.
15.3 Klarivox shall, on request, certify in writing that it has complied with this clause 15.
16Liability
Each Party's liability arising out of or in connection with this DPA shall be subject to the limitations and exclusions of liability set out in the Principal Agreement. Nothing in this DPA limits any liability that cannot be excluded or limited under Applicable Data Protection Law, including the rights of data subjects under Articles 79 and 82 of the GDPR.
17Term and Termination
This DPA takes effect on the date of the Principal Agreement and continues for as long as Klarivox processes Customer Personal Data on behalf of the Controller. Termination of the Principal Agreement automatically terminates this DPA, save for provisions that by their nature are intended to survive (including clauses 12, 14, 15, 16, and 18).
18Governing Law, Disputes, and General Provisions
18.1 This DPA is governed by Danish law. The Parties submit to the courts of Denmark, save where Applicable Data Protection Law requires the application of the law or jurisdiction of the data subject's habitual residence.
18.2 If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force, and the invalid provision shall be modified to the minimum extent necessary to make it valid and enforceable while preserving the Parties' commercial intent.
18.3 No amendment of this DPA is effective unless made in writing and signed by both Parties, except that Klarivox may update Annex II in accordance with clause 8.3 and Annex III in accordance with clause 9.3.
18.4 This DPA may be signed in counterparts, including by electronic signature.
Annex I Description of Processing Parties, data subjects, categories, retention, supervisory authority
A. List of Parties
Data exporter (Controller)
| Name | [Customer legal name] |
| Address | [Customer registered address] |
| DPO / privacy contact | [Customer DPO or privacy contact, email] |
| Activities relevant to transfer | Use of the Klarivox software-as-a-service platform under the Principal Agreement |
| Role | Controller |
| Company registration no. | [Customer CVR or equivalent] |
Data importer (Processor)
| Name | Klarivox ApS |
| CVR | 46445104 |
| Address | Glamsbjergvej 15, 2770 Kastrup, Denmark |
| Privacy contact | privacy@getklarivox.com |
| Activities relevant to transfer | Operation of the Klarivox SaaS platform: ingestion, analysis, and presentation of customer conversation data linked to CRM data, on behalf of the Controller |
| Role | Processor |
B. Description of Transfer
| Categories of data subjects | Controller's customers, prospects, leads, and end users; Controller's employees and contractors who participate in conversations or appear in CRM records; participants in customer interviews, surveys, support tickets, and NPS responses |
| Categories of personal data | Identification data (name, email, phone, company, job title); contact and communication content (call transcripts, emails, support ticket bodies, chat messages, review content, NPS responses); CRM data (account, deal, and opportunity metadata, including contact names and notes) |
| Sensitive data | No sensitive data (Art. 9 GDPR) is intended to be processed. To the extent such data is incidentally included in customer-uploaded content, the Controller is responsible for ensuring an appropriate lawful basis and additional safeguards. |
| Frequency of transfer | Continuous, for the duration of the Principal Agreement |
| Nature of processing | Collection, recording, organisation, storage, retrieval, use, analysis (including by automated means and by AI sub-processors), disclosure to authorised users of the Controller, and erasure |
| Purpose | Providing the Klarivox platform: ingestion of conversation data; extraction of themes, pains, and signals; ranking by revenue weighting; visualisation; alerts and digests; and related support services |
| Duration / retention | For the duration of the Principal Agreement, plus the deletion period set out in clause 15.2 |
| Sub-processor transfers | See Annex III and getklarivox.com/subprocessors |
C. Competent Supervisory Authority
Datatilsynet (the Danish Data Protection Authority)
Carl Jacobsens Vej 35, 2500 Valby,
Denmark
dt@datatilsynet.dk
Annex II Technical and Organisational Measures Security controls Klarivox commits to maintain
Klarivox commits to maintain the following technical and organisational measures for the duration of the Principal Agreement, subject to update under clause 8.3.
Data protection
- Encryption in transit: TLS 1.3 or higher for all network connections, including between internal services.
- Encryption at rest: AES-256 at the storage layer on all customer data stores, backups, and object storage.
- Data residency: Customer data is hosted by a European company inside the EU. Enterprise contracts may specify a different region by agreement.
- Backups: Automated daily encrypted backups, multi-zone within region, retained for 90 days.
- Deletion & portability: Customer data is exported or deleted on request, in a structured, commonly used format. On termination, data is deleted within 90 days; backup copies roll off on the standard cycle.
Access & identity
- Mandatory MFA for all Klarivox employees and contractors accessing production systems.
- Role-based access control (RBAC) on the principle of least privilege; access reviews are conducted quarterly.
- Automated deprovisioning on employee termination or role change.
- Audit logs of authentication, access, and administrative actions, retained for 24 months and available on request.
- No shared accounts for production access — every action is attributable to a named individual.
Infrastructure
- Cloud provider: Hosted in an EU region; development and production environments are separated.
- Network controls: Network access restricted to required ports and IP ranges; WAF and DDoS protection in front of public-facing services.
- Tenant isolation: Workspace-level logical isolation enforced at the application and database layer; access controls prevent cross-tenant data access.
Application security
- Automated security testing in CI: static analysis (SAST), secret scanning, dependency vulnerability checks.
- Timely patching of known vulnerabilities; critical fixes prioritised against published SLAs.
- Independent penetration testing by an external firm, to be performed annually, targeted for Q3 2027; executive summaries will be available to customers under NDA once the first test is complete.
- Bug bounty: Coordinated disclosure programme for good-faith security researchers (security@getklarivox.com).
AI processing
- Klarivox uses large language models from a third-party provider to extract themes, sentiment, and signals from customer-uploaded conversations. Prompts and completions are not used to train the provider's models.
- No Klarivox-owned model is trained on customer data without express written consent.
- AI processing is invoked only as needed to serve specific product features; data is not sent to a model on a speculative basis.
Incident response
- Tabletop exercises, to be conducted annually, first targeted for Q1 2027, to validate readiness and update playbooks.
- Customer notification without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach, in accordance with clause 12.
- Post-incident reports are shared with affected customers, including root cause and remediation.
People & process
- Written confidentiality obligations for all employees and contractors with access to customer data.
- Security and data-protection training, delivered annually, with role-specific training for engineering and customer-facing teams.
- Vendor assessment before engaging any sub-processor that handles customer data, plus ongoing reviews.
- Business continuity: BC/DR plans, to be documented and tested annually including data restoration drills, targeted for Q1 2027.
Annex III Sub-processors Current list of third-party processors engaged by Klarivox
The following Sub-processors may process Customer Personal Data uploaded to, or generated by, the Klarivox platform. The current and authoritative version of this list is maintained under the heading "Sub-processors of customer data" at getklarivox.com/subprocessors, subject to the notice and objection rights in clause 9.
| Sub-processor | Purpose | Data categories | Location | Mechanism |
|---|---|---|---|---|
| UpCloud Oy | Cloud hosting, storage, compute, networking | All customer-uploaded data; account data; logs | EU regions | EEA — no transfer |
| Mistral AI | Large language model inference for theme extraction and summarisation | Content passed to the model from customer-uploaded data | EU regions | EEA — no transfer |
| Mailgun Technologies, Inc. (Sinch Email) | Transactional email delivery for account, authentication, billing, and service notifications | Recipient name and email address; sender address; subject and message body; delivery status, timestamps, bounce and event metadata. No customer-uploaded conversation content. | EU infrastructure; limited non-EEA administrative and support access | EEA storage · DPF · SCCs |
The page linked below maintains a change log recording additions and replacements. The "Other service providers" table on that page is disclosed for transparency and does not form part of this Annex III.
getklarivox.com/subprocessors
Full sub-processor list with purposes, locations, transfer mechanisms, and change notices under clause 9.3.